CVE-2025-57624
7.8CYRISMA · Agent
A DLL hijacking vulnerability in the CYRISMA Agent allows local authenticated users to escalate privileges and execute arbitrary code by leveraging multiple vulnerable DLL files.
Executive summary
A DLL hijacking vulnerability in CYRISMA Agent versions prior to 444 presents a significant risk of local privilege escalation and arbitrary code execution.
Vulnerability
The software is susceptible to DLL hijacking, which allows a local attacker with low privileges to execute arbitrary code or escalate privileges by placing malicious DLLs in locations where the agent expects to load them.
Business impact
Successful exploitation of this vulnerability allows a local attacker to gain elevated privileges on the host machine. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to full system compromise, unauthorized data access, and potential lateral movement within the network.
Remediation
Immediate Action: Update the CYRISMA Agent to version 444 or later immediately to resolve the vulnerable DLL loading behavior.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unauthorized files being created in agent installation directories.
Compensating Controls: Restrict local user access to the installation directories of the CYRISMA Agent to prevent the placement of malicious DLL files.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists as documented in the linked research write-up and video reference.
Analyst recommendation
The risk posed by local privilege escalation is significant in environments where endpoint integrity is critical. Administrators must prioritize updating the CYRISMA Agent to version 444 or later across all managed endpoints to eliminate the underlying DLL hijacking vector. Failure to patch may allow attackers who have gained limited initial access to fully compromise the affected host.